Courseiva
Security →mediumMultiple Choice

XK0-006 Security Practice Question

A Linux administrator needs to configure a system to use a central authentication service. The service requires that user credentials are sent over the network in an encrypted format and that the client validates the server's certificate. Which of the following should the administrator configure?

⚠ Common exam trap

A common mix-up: candidates confuse encryption with certificate validation; some options encrypt traffic but do not verify the server's identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure LDAP with TLS using the ldaps:// URI and set TLS_REQCERT to demand in /etc/ldap/ldap.conf.

LDAP with TLS (LDAPS) encrypts authentication traffic, and setting TLS_REQCERT to demand ensures the client validates the server's certificate. This combination meets both the encryption and validation requirements. The other options either lack certificate validation or use insecure protocols.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Kerberos with a keytab file and set the default realm in /etc/krb5.conf.

    Why it's wrong here

    Kerberos provides strong authentication and can encrypt tickets, but it does not inherently validate server certificates in the same way TLS does. The keytab file is used for service authentication, not for client-side certificate validation. This option does not explicitly address certificate validation and may not encrypt all credential exchanges depending on the setup.

  • ✗

    Configure NIS with a secured map and use ypbind with a password.

    Why it's wrong here

    NIS is an outdated and insecure protocol that does not encrypt authentication traffic by default. Even with a 'secured' map, it lacks modern encryption and certificate validation. This does not meet the requirements for encrypted credentials and server certificate validation. NIS should be avoided in favor of more secure alternatives.

  • ✗

    Configure SSSD with ldap_id_use_start_tls = true and ldap_tls_reqcert = never.

    Why it's wrong here

    Setting ldap_tls_reqcert = never disables certificate validation, which violates the requirement to validate the server's certificate. While start_tls encrypts the connection, the lack of certificate validation makes it vulnerable to man-in-the-middle attacks. This configuration does not meet the security requirements.

  • ✓

    Configure LDAP with TLS using the ldaps:// URI and set TLS_REQCERT to demand in /etc/ldap/ldap.conf.

    Why this is correct

    Using LDAPS (LDAP over TLS) encrypts the authentication traffic. Setting TLS_REQCERT to demand enforces certificate validation, ensuring the client verifies the server's certificate. This meets both the encryption and validation requirements. It is a standard way to secure LDAP communications.

About these practice questions

This XK0-006 question is part of Courseiva's 781-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This XK0-006 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the XK0-006 exam.